-
Notifications
You must be signed in to change notification settings - Fork 28k
/
trustedDomains.test.ts
137 lines (111 loc) · 5.63 KB
/
trustedDomains.test.ts
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
/*---------------------------------------------------------------------------------------------
* Copyright (c) Microsoft Corporation. All rights reserved.
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/
import * as assert from 'assert';
import { isURLDomainTrusted } from 'vs/workbench/contrib/url/browser/trustedDomainsValidator';
import { URI } from 'vs/base/common/uri';
import { extractGitHubRemotesFromGitConfig } from 'vs/workbench/contrib/url/browser/trustedDomains';
function linkAllowedByRules(link: string, rules: string[]) {
assert.ok(isURLDomainTrusted(URI.parse(link), rules), `Link\n${link}\n should be allowed by rules\n${JSON.stringify(rules)}`);
}
function linkNotAllowedByRules(link: string, rules: string[]) {
assert.ok(!isURLDomainTrusted(URI.parse(link), rules), `Link\n${link}\n should NOT be allowed by rules\n${JSON.stringify(rules)}`);
}
suite('GitHub remote extraction', () => {
test('All known formats', () => {
assert.deepStrictEqual(
extractGitHubRemotesFromGitConfig(
`
[remote "1"]
url = git@github.com:sshgit/vscode.git
[remote "2"]
url = git@github.com:ssh/vscode
[remote "3"]
url = https://github.com/httpsgit/vscode.git
[remote "4"]
url = https://github.com/https/vscode`),
[
'https://github.com/sshgit/vscode/',
'https://github.com/ssh/vscode/',
'https://github.com/httpsgit/vscode/',
'https://github.com/https/vscode/'
]);
});
});
suite('Link protection domain matching', () => {
test('simple', () => {
linkNotAllowedByRules('https://x.org', []);
linkAllowedByRules('https://x.org', ['https://x.org']);
linkAllowedByRules('https://x.org/foo', ['https://x.org']);
linkNotAllowedByRules('https://x.org', ['http://x.org']);
linkNotAllowedByRules('http://x.org', ['https://x.org']);
linkNotAllowedByRules('https://www.x.org', ['https://x.org']);
linkAllowedByRules('https://www.x.org', ['https://www.x.org', 'https://y.org']);
});
test('localhost', () => {
linkAllowedByRules('https://127.0.0.1', []);
linkAllowedByRules('https://127.0.0.1:3000', []);
linkAllowedByRules('https://localhost', []);
linkAllowedByRules('https://localhost:3000', []);
});
test('* star', () => {
linkAllowedByRules('https://a.x.org', ['https://*.x.org']);
linkAllowedByRules('https://a.b.x.org', ['https://*.x.org']);
});
test('no scheme', () => {
linkAllowedByRules('https://a.x.org', ['a.x.org']);
linkAllowedByRules('https://a.x.org', ['*.x.org']);
linkAllowedByRules('https://a.b.x.org', ['*.x.org']);
linkAllowedByRules('https://x.org', ['*.x.org']);
});
test('sub paths', () => {
linkAllowedByRules('https://x.org/foo', ['https://x.org/foo']);
linkAllowedByRules('https://x.org/foo/bar', ['https://x.org/foo']);
linkAllowedByRules('https://x.org/foo', ['https://x.org/foo/']);
linkAllowedByRules('https://x.org/foo/bar', ['https://x.org/foo/']);
linkAllowedByRules('https://x.org/foo', ['x.org/foo']);
linkAllowedByRules('https://x.org/foo', ['*.org/foo']);
linkNotAllowedByRules('https://x.org/bar', ['https://x.org/foo']);
linkNotAllowedByRules('https://x.org/bar', ['x.org/foo']);
linkNotAllowedByRules('https://x.org/bar', ['*.org/foo']);
linkAllowedByRules('https://x.org/foo/bar', ['https://x.org/foo']);
linkNotAllowedByRules('https://x.org/foo2', ['https://x.org/foo']);
linkNotAllowedByRules('https://www.x.org/foo', ['https://x.org/foo']);
linkNotAllowedByRules('https://a.x.org/bar', ['https://*.x.org/foo']);
linkNotAllowedByRules('https://a.b.x.org/bar', ['https://*.x.org/foo']);
linkAllowedByRules('https://github.com', ['https://github.com/foo/bar', 'https://github.com']);
});
test('ports', () => {
linkNotAllowedByRules('https://x.org:8080/foo/bar', ['https://x.org:8081/foo']);
linkAllowedByRules('https://x.org:8080/foo/bar', ['https://x.org:*/foo']);
linkAllowedByRules('https://x.org/foo/bar', ['https://x.org:*/foo']);
linkAllowedByRules('https://x.org:8080/foo/bar', ['https://x.org:8080/foo']);
});
test('ip addresses', () => {
linkAllowedByRules('http://192.168.1.7/', ['http://192.168.1.7/']);
linkAllowedByRules('http://192.168.1.7/', ['http://192.168.1.7']);
linkAllowedByRules('http://192.168.1.7/', ['http://192.168.1.*']);
linkNotAllowedByRules('http://192.168.1.7:3000/', ['http://192.168.*.6:*']);
linkAllowedByRules('http://192.168.1.7:3000/', ['http://192.168.1.7:3000/']);
linkAllowedByRules('http://192.168.1.7:3000/', ['http://192.168.1.7:*']);
linkAllowedByRules('http://192.168.1.7:3000/', ['http://192.168.1.*:*']);
linkNotAllowedByRules('http://192.168.1.7:3000/', ['http://192.168.*.6:*']);
});
test('scheme match', () => {
linkAllowedByRules('http://192.168.1.7/', ['http://*']);
linkAllowedByRules('http://twitter.com', ['http://*']);
linkAllowedByRules('http://twitter.com/hello', ['http://*']);
linkNotAllowedByRules('https://192.168.1.7/', ['http://*']);
linkNotAllowedByRules('https://twitter.com/', ['http://*']);
});
test('case normalization', () => {
// https://github.com/microsoft/vscode/issues/99294
linkAllowedByRules('https://github.com/microsoft/vscode/issues/new', ['https://github.com/microsoft']);
linkAllowedByRules('https://github.com/microsoft/vscode/issues/new', ['https://github.com/microsoft']);
});
test('ignore query & fragment - https://github.com/microsoft/vscode/issues/156839', () => {
linkAllowedByRules('https://github.com/login/oauth/authorize?foo=4', ['https://github.com/login/oauth/authorize']);
linkAllowedByRules('https://github.com/login/oauth/authorize#foo', ['https://github.com/login/oauth/authorize']);
});
});